IBM documented the Mozi botnet compromising vulnerable Internet of Things (IoT) devices through command injection and delivering a payload named mozi.a. Exposed web and debugging interfaces, exploitable PHP modules, inadequate input sanitization, and delayed patching enable inexpensive, automated attacks. The analyzed payload targets MIPS architecture, and associated artifacts include network bootstrap endpoints, credential strings, firewall commands, and device-management configuration changes. India's Cyber Swachhta Kendra also published an alert on the Mozi IoT botnet.
IBM reported that 84% of observed Mozi infrastructure was sourced in China; that finding does not establish the operators' nationality or state affiliation. The supplied material does not identify specific vulnerabilities or CVEs, limiting vulnerability-specific remediation guidance. Organizations should prioritize inventorying exposed IoT devices, restricting access to management and debugging interfaces, applying vendor patches, and monitoring for unexpected outbound connections or unauthorized firewall and device-configuration changes.

See which actors are running it and whether you're in range.
1 event from the most recent confirmed update back to the earliest known activity.
IBM reported that Mozi exploited vulnerable IoT interfaces through command injection to deliver the MIPS-targeting mozi.a payload, and supplied network endpoints, credentials, firewall commands, and device-management artifacts. IBM found that 84% of observed Mozi infrastructure was sourced in China, without establishing the operators’ nationality or state affiliation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.